PT-2020-10395 · Trend Micro · Trend Micro Anti-Threat Toolkit
Stefan Kanthak
·
Published
2020-01-30
·
Updated
2021-07-21
·
CVE-2019-20358
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below
Description
The issue may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. An attack vector similar to a previously identified vulnerability was discovered and resolved in a later version of the tool.
Recommendations
For versions 1.62.0.1218 and below, update to version 1.62.0.1228 or later to resolve the issue.
Fix
RCE
Incorrect Permission
Uncontrolled Search Path Element
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Anti-Threat Toolkit